Casky.AI
ApproachPathsBlogAboutCommunity
Sign inGet Access
↗Based on the popular Anthropic Cybersecurity Skills & Agents open-source repo
26.5k stars·3.2k forksfeatured in★awesome-agent-skills·SkillsLLM·OpenflowsApache 2.0·Open source

AI Security Investigation

Run real investigations.
Ship professional findings.

A CVE drops. Your multi-agent pipeline has an investigation plan in under 5 minutes. Ingest real logs, configs, or incident data and Casky's agents generate a structured plan your team approves, then execute in parallel to produce CVSS-scored, MITRE-mapped findings.

Find Your First Real Vulnerability — FreeSee how it works
817
AI-powered skills
5
Investigation paths
< 5 min
Evidence → findings
RJ
MJ

Built by practitioners.
15+ years of real engagements →

CISO-Ready Investigation Platform

What CISOs need from every investigation

Casky's structured findings answer the 5 questions your board and CISO ask — automatically, every time.

What happened?

Evidence Mode takes your logs, alerts, and configs directly — your analyst pastes the evidence, not a description of it.

What were the findings?

Every run produces a structured finding: title, CVSS score, severity, affected asset, and MITRE technique ID — formatted for a ticket or an executive report.

What were the fixes?
mapped to
MITRE ATT&CK14 tactics · 291 techniques
NIST CSF 2.06 functions · full lifecycle
OWASP Top 102025 edition
Claude Sonnet 4.6Multi-Agent Investigation Pipeline

Why Casky

Makes SOC analysts better, faster,
and smarter as a team.

Makes good analysts better.

Security orchestration automates the playbook, but only for known patterns. When the threat is new, the playbook runs out and the alert queue grows.

Casky generates a structured MITRE-mapped investigation plan from raw evidence. Every technique is anchored to a specific log artifact, every step in causal order. Not a chat window. A structured workflow your analyst can scan and approve in 60 seconds.

No one analyst knows everything.

Enterprise platforms work on data already normalized into their ecosystem. A cloud IAM anomaly, an endpoint artifact, a network capture. Each lives in a different tool, a different analyst, no shared context.

Casky lets your team pool any evidence into one investigation plan. The AI planner sees everything. Your team's rated cases calibrate every future plan. Institutional knowledge that compounds automatically.

Your best work trains your next analyst.

Tabletop exercises and lab scenarios use synthetic infrastructure. Your junior analysts learn from cases that look nothing like yours.

Every rated Casky investigation is a step-by-step training artifact from your real environment — evidence, MITRE rationale, findings, and CISO output. Senior work becomes the curriculum.

The approach

The investigation platform built for
how security actually works

Real evidence in. Structured, CVSS-scored, MITRE-mapped findings out. The way security work gets done.

Multi-Agent Pipeline

A specialist agent validates MITRE techniques against your evidence anchors. A domain-tuned agent selects only the skills your deployment can actually run. Two more agents order the steps and surface evidence gaps — all before a single skill executes.

vs. passive video courses

Framework-Native

Every skill maps to MITRE ATT&CK tactics, NIST CSF functions, and OWASP categories. You always know exactly where your knowledge sits in the industry map.

The workflow

How Casky works

01

Ingest your evidence

Paste logs, upload files, or drop a CloudTrail export. Any source, any format.

02

Context assembles automatically

CVE exposure, matched investigation playbooks, and your team's rated past cases — assembled in parallel before any AI touches your evidence.

03

Review and approve the plan

Four specialist agents generate a MITRE-mapped plan, each step with a rationale and expected finding. You edit and approve before anything runs.

04

The platform

See it in action

A real look at the Casky Playground.

Your mission control — runs, findings, and activity at a glance
Dashboard
Your mission control — runs, findings, and activity at a glance
Real-time overview of your security work
Dashboard
Real-time overview of your security work
Pick a skill, set your target, run a Claude agent
Skills Lab
Pick a skill, set your target, run a Claude agent
Navigate the curriculum by MITRE, NIST, or OWASP
Learning Path
Navigate the curriculum by MITRE, NIST, or OWASP
Track every agent run directly from your dashboard
Dashboard — Runs
Track every agent run directly from your dashboard
All your CVSS-scored findings in one view
Dashboard — Findings
All your CVSS-scored findings in one view
From agent run to structured security finding
Runs & Findings
From agent run to structured security finding
Detailed run output with linked findings
Runs & Findings
Detailed run output with linked findings
Claude reasoning live through a security problem
Skills Run
Claude reasoning live through a security problem
Full run history with status, target, and timing
Runs
Full run history with status, target, and timing
Stream Claude's agent reasoning in real time
Run Detail
Stream Claude's agent reasoning in real time
From findings to a professional assessment report
Reports & Findings
From findings to a professional assessment report
Export full reports — executive summary, findings, remediation
Reports
Export full reports — executive summary, findings, remediation
817 skills mapped to MITRE ATT&CK, NIST CSF, and OWASP
Skills Registry
817 skills mapped to MITRE ATT&CK, NIST CSF, and OWASP
CVSS-scored findings tagged to MITRE techniques
Findings
CVSS-scored findings tagged to MITRE techniques

817 skills · 12 domains

Every security domain, covered.

Not just cloud. Not just web. From OSINT to container security, Casky covers the full attack surface. The investigation pipeline adapts to whatever evidence you bring.

OSINT & Recon
0 skills
TA0043NIST ID
Web App & API Security
70 skills
OWASP A01–A10

Built for every practitioner

Democratizing cybersecurity for everyone.

From network security to cloud security to penetration testing — Casky is for every practitioner. The investigation plan adapts to your role. Same evidence in. Role-aware plan out.

Cloud Security Engineer

IAM escalation · S3 exposure · cross-account access · GuardDuty findings

TA0004NIST PR

Network Security Engineer

Traffic anomalies · lateral movement · C2 detection · DNS tunneling

Built forSOC AnalystsSecurity Leads & CISOsJunior PractitionersSecurity ConsultantsSMB Security Teams
Early access — Playground waitlist now open

Run your first real
investigation — free.

Paste your evidence. Get CVSS-scored, MITRE-mapped findings. No simulation. No CTF flags. Your actual security work — with 817 AI-powered skills behind it. Free for early members.

We'll email you when the Playground opens. No spam. Unsubscribe anytime.

817
Skills in Playground
Free
For early members
Async
Learn at your pace
Casky.AI, Inc.· AI-Powered Cyber Skills
AboutEnterpriseCommunityContributeSign inContact
XInstagramLinkedIn
claude-agent · OWASP A03: Injection
running
01▶ target: demo.testfire.net
02 loading: SQL Injection Detection
03 mapping: MITRE T1190 · OWASP A03
04 probing /login — testing 8 vectors
05⚠ anomalous response on: username
06 testing boolean-based blind inject...
07✗ CONFIRMED: Blind SQLi at /login
08 estimating blast radius...
09✓ report_finding("SQL Injection", "critical")
10 CVSS: 9.8 · CWE-89 · T1190
11 generating remediation guidance ▌

Each finding includes a specific remediation step your team can act on immediately. No interpretation required.

How do we prevent this from happening again?

MITRE ATT&CK tags on every finding tell you exactly which tactic was exploited — and which skills your team can run to close that gap.

Am I covered?

Assign a Learning Path to each role on your team. Analysts complete structured paths (101 → 201 → Certificate) and earn verifiable credentials per domain.

Run a free investigation →Building a security team? →

vs. random skill tutorials

Every run produces a real finding

Not a score. Not a summary. A structured finding: title, CVSS score, affected asset, MITRE technique ID, and a specific remediation step — the exact format used in client reports and CISO briefings.

vs. generic vulnerability scanners

Agents run in parallel

Each approved step executes as a skill run. CVSS-scored, technique-tagged findings land as they complete.

05

Generate the CISO report

One click. Executive summary, confirmed MITRE techniques, findings table, prioritised remediation. The format used in real engagements.

Malware Analysis
39 skills
TA0002NIST DE
Cloud & Infrastructure
66 skills
TA0004NIST PR
Digital Forensics & IR
67 skills
TA0040NIST RS
Network Security
43 skills
TA0011NIST DE
Identity & Access
54 skills
TA0006NIST PR
Red Teaming
54 skills
AllNIST ID
DevSecOps
18 skills
NIST PROWASP A03,A08
Threat Intelligence
110 skills
TA0043NIST ID
SOC Operations
35 skills
NIST DE/RS
Container Security
33 skills
NIST PROWASP A05,A06
TA0011NIST DE

Web & App Security Engineer

OWASP Top 10 · API abuse · auth bypass · injection chains

OWASP A01–A10

SOC Analyst

Alert triage · threat detection · incident timeline · CISO escalation

TA0040NIST DE/RS

Penetration Tester

Recon · exploitation · privilege escalation · engagement report

AllNIST ID
TikTok
TermsPrivacyLegal Disclaimer

© 2026 Casky.AI, Inc. · AI Security Investigation